Back to skill

Security audit

alibabacloud-cms-manage

Security checks for vulnerabilities and agentic risk

Overview

The skill is coherent for Alibaba Cloud monitoring management, but it needs Review because it can change cloud and Kubernetes resources and includes unsafe agent-install and credential-handling workflows.

Install only if you are comfortable letting the agent guide high-impact Alibaba Cloud and Kubernetes operations. Review every generated command before approving it, prefer pinned and verified agent/package installation methods, avoid pipe-to-shell installers, use temporary isolated kubeconfig files instead of ~/.kube/config, and keep monitoring tokens out of logs, images, and shared chat transcripts.

Vulnerability Patterns
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (4)

T03 · Remote Payload Retrieval and Execution

Error
Location
references/apm.md:383
Finding

Java monitoring agent downloaded over plaintext HTTP and executed without integrity verification

Content
View full analysis

Vulnerability Details

File Location: references/apm.md:383-384
Vulnerability Type: Remote payload retrieval and execution
Risk Level: High

bash
wget -T 30 -t 3 "http://arms-apm-{regionId}.oss-{regionId}[-internal].aliyuncs.com/AliyunJavaAgent.zip" -O AliyunJavaAgent.zip
unzip AliyunJavaAgent.zip -d /opt/

Technical Analysis

The workflow downloads an executable Java monitoring agent over plaintext HTTP and extracts it into /opt/ without verifying a cryptographic signature, checksum, pinned version, or trusted final download destination.

Because HTTP does not provide transport integrity or server authentication, a network-positioned attacker could replace the ZIP archive in transit. A compromised object-storage account, DNS path, proxy, or delivery endpoint could produce the same result. The extracted JAR is subsequently loaded using Java's -javaagent mechanism, so its initialization code executes inside the monitored JVM.

No archive-content validation is required before extraction. A malicious archive could therefore also contain unexpected files or path traversal entries, depending on the behavior and version of the local extraction utility.

Attack Path

  1. A user follows the documented Java onboarding workflow.
  2. The host downloads AliyunJavaAgent.zip through an unencrypted HTTP connection.
  3. An attacker with control over the network path, DNS resolution, proxy, storage object, or delivery endpoint substitutes a modified archive.
  4. The untrusted archive is extracted into /opt/ without checksum or signature verification.
  5. The application is restarted with the downloaded JAR specified through -javaagent.
  6. The substituted code executes with the same operating-system identity and effective privileges as the Java application.

Impact Assessment

Successful exploitation provides arbitrary code execution within the instrumented Java process. The payload could access appli ...[truncated 451 chars]

Remediation
View remediation

Remediation Suggestions

  1. Require HTTPS for every public and VPC download endpoint.
  2. Pin an explicit, reviewed agent version rather than retrieving a mutable default artifact.
  3. Publish an expected SHA-256 or stronger digest through an independently authenticated channel and verify it before extraction.
  4. Prefer vendor-signed artifacts and validate the signature against a pinned vendor public key.
  5. Disable or strictly validate redirects, and allow only approved Alibaba Cloud hostnames.
  6. Inspect ZIP entries before extraction and reject absolute paths, symbolic links, and ../ traversal entries.
  7. Download to a restricted temporary directory, validate the artifact, and only then install it into /opt/.
  8. Run the application and agent under a dedicated, least-privileged operating-system account.
  9. Abort installation when any transport, checksum, signature, hostname, or archive validation fails.

T08 · Insecure Dependencies

Warning
Location
references/apm.md:541
Finding

Unpinned Python bootstrap package is installed and immediately executed

Content
View full analysis

Vulnerability Details

File Location: references/apm.md:541-545
Vulnerability Type: Insecure dependency installation
Risk Level: Medium

bash
pip3 install aliyun-bootstrap
aliyun-bootstrap -a install

export ARMS_APP_NAME={appName}
export ARMS_WORKSPACE={workspace}
export ARMS_REGION_ID={regionId}
export ARMS_LICENSE_KEY={LicenseKey}

Technical Analysis

The workflow installs aliyun-bootstrap without pinning a version or verifying package hashes and then immediately executes the installed command. The effective code can therefore change after the Skill has been reviewed.

The package itself or one of its transitive dependencies could be altered through a compromised publisher account, malicious release, package-index compromise, dependency confusion, or unexpected upstream update. Python package installation can also execute build backend logic, while the subsequent aliyun-bootstrap -a install command explicitly runs package-supplied code.

Attack Path

  1. An attacker compromises the package publisher, package index, release process, or a transitive dependency.
  2. A malicious version becomes the version selected by pip3 install aliyun-bootstrap.
  3. A user follows the onboarding workflow and installs that mutable version.
  4. Package build logic or the immediately invoked aliyun-bootstrap -a install command executes attacker-controlled code.
  5. The malicious component persists in the Python environment or modifies the monitoring instrumentation loaded by the application.
  6. When the application runs, the compromised instrumentation can access application data and the configured monitoring credential.

Impact Assessment

The malicious package obtains the privileges of the account performing installation and execution. It could modify the Python environment, application files, startup configuration, or installed instrumentation.

Once loaded into the monitored application, it ...[truncated 223 chars]

Remediation
View remediation

Remediation Suggestions

  1. Pin aliyun-bootstrap to an explicitly reviewed version.
  2. Install from a locked requirements file using hashes, such as pip install --require-hashes -r requirements.txt.
  3. Pin and hash all transitive dependencies.
  4. Use a trusted, access-controlled package mirror and enforce package provenance where supported.
  5. Build and scan the dependency in an isolated environment before deploying it to application hosts.
  6. Run installation and bootstrap operations under a dedicated, non-administrative account.
  7. Separate package download, verification, installation, and execution into distinct reviewable steps.
  8. Establish a controlled dependency update process rather than automatically accepting the latest package release.

T08 · Insecure Dependencies

Warning
Location
references/apm.md:561
Finding

Docker build installs and executes an unpinned monitoring bootstrap package

Content
View full analysis

Vulnerability Details

File Location: references/apm.md:561-568
Vulnerability Type: Insecure dependency installation in container build
Risk Level: Medium

dockerfile
ENV ARMS_APP_NAME={appName}
ENV ARMS_REGION_ID={regionId}
ENV ARMS_LICENSE_KEY={LicenseKey}
ENV ARMS_WORKSPACE={workspace}
RUN pip3 install aliyun-bootstrap && ARMS_REGION_ID={regionId} aliyun-bootstrap -a install
CMD ["aliyun-instrument", "python", "app.py"]

Technical Analysis

The Dockerfile installs a mutable version of aliyun-bootstrap and executes it during image construction. The resulting instrumentation is then loaded when the container starts through aliyun-instrument.

The build does not pin a package version, verify package hashes, or use a dependency lockfile. Consequently, rebuilding the same source at different times can produce different executable images. A compromised package release or dependency can execute during the build and alter the final image.

The example also places ARMS_LICENSE_KEY in a Dockerfile ENV instruction. If a real credential is substituted during image construction, it becomes part of the image configuration and may be exposed through image inspection, registries, caches, deployment tooling, or users with image-read access.

Attack Path

  1. An attacker publishes or causes selection of a compromised aliyun-bootstrap package or transitive dependency.
  2. A container build executes pip3 install aliyun-bootstrap without version or hash restrictions.
  3. Package build hooks or aliyun-bootstrap -a install execute in the build environment.
  4. The malicious package modifies the image or installed instrumentation.
  5. The resulting image is distributed through the normal registry and deployment pipeline.
  6. Each container starts through the compromised aliyun-instrument entry point.
  7. If a real LicenseKey was embedded at build time, anyone with sufficient image metadata ...[truncated 643 chars]
Remediation
View remediation

Remediation Suggestions

  1. Pin the package and all transitive dependencies to reviewed versions with verified hashes.
  2. Build from a locked requirements file and fail the build on any hash mismatch.
  3. Use a trusted internal package mirror and retain package provenance records.
  4. Scan the built image and generate a software bill of materials before deployment.
  5. Never place a real LicenseKey in a Dockerfile ENV, build argument, image layer, or build cache.
  6. Inject the credential only at runtime through a Kubernetes Secret, container secret manager, or equivalent protected mechanism.
  7. Restrict registry and build-cache access and rotate any credential that may already have been embedded in an image.
  8. Run the final container as a non-root user with a read-only root filesystem and minimal Linux capabilities.

T08 · Insecure Dependencies

Warning
Location
references/apm.md:619
Finding

Unpinned Node.js monitoring SDK is installed and preloaded into the application process

Content
View full analysis

Vulnerability Details

File Location: references/apm.md:619-630
Vulnerability Type: Insecure dependency installation
Risk Level: Medium

bash
npm install @loongsuite/cms_node_sdk
bash
export ARMS_LICENSE={LicenseKey}
export CMS_SERVICE_NAME={appName}
export ARMS_REGION_ID={regionId}
export ARMS_WORKSPACE={workspace}
node -r @loongsuite/cms_node_sdk/register app.js

Technical Analysis

The workflow installs @loongsuite/cms_node_sdk without a pinned version or lockfile and then preloads the package into the Node.js application with -r.

NPM packages may execute lifecycle scripts during installation. The -r option additionally causes the package's registration module to execute before the application entry point, inside the application process. A compromised package release, publisher account, registry response, or transitive dependency would therefore have a direct execution path.

Attack Path

  1. An attacker compromises the SDK publisher, package registry, release pipeline, or a transitive dependency.
  2. The user runs the unversioned npm install command.
  3. Malicious lifecycle scripts may execute during installation.
  4. The application starts with -r @loongsuite/cms_node_sdk/register.
  5. The compromised registration module executes before app.js.
  6. The module reads application state, environment variables, and monitoring credentials or alters application behavior and telemetry.

Impact Assessment

The package executes with the privileges of the installing user during installation and with the application's privileges at runtime. Because it is preloaded before the application, it can intercept module loading, network requests, framework hooks, database calls, and telemetry.

It can access ARMS_LICENSE, application secrets, service credentials, and any files or network endpoints available to the Node.js process.

Remediation
View remediation

Remediation Suggestions

  1. Pin the SDK to a reviewed exact version.
  2. Commit and enforce a lockfile, and use npm ci rather than unconstrained npm install.
  3. Verify package provenance, integrity metadata, publisher identity, and expected package contents.
  4. Audit and pin all transitive dependencies.
  5. Disable lifecycle scripts during installation when they are unnecessary, or explicitly review every required script.
  6. Retrieve dependencies through a trusted, access-controlled registry mirror.
  7. Test and scan the exact dependency set before production deployment.
  8. Run the Node.js service under a dedicated, least-privileged account and limit access to credentials and sensitive files.
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Memory PoisoningPersistent Context Injection, Context Window Stuffing, Memory Manipulation
Findings (78)

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 68)May include surrounding context.

md
ch field's `fieldPath` into nested JSON as specified in [Addon Values Defaults](references/integration-common.md#addon-values-defaults-hard-requirement). Do not

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 72)May include surrounding context.

md
ch field's `fieldPath` into nested JSON as specified in [Addon Values Defaults](references/integration-common.md#addon-values-defaults-hard-requirement). Do not

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 92)May include surrounding context.

md
ch field's `fieldPath` into nested JSON as specified in [Addon Values Defaults](references/integration-common.md#addon-values-defaults-hard-requirement). Do not

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 183)May include surrounding context.

md
ch field's `fieldPath` into nested JSON as specified in [Addon Values Defaults](references/integration-common.md#addon-values-defaults-hard-requirement). Do not

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 189)May include surrounding context.

md
ch field's `fieldPath` into nested JSON as specified in [Addon Values Defaults](references/integration-common.md#addon-values-defaults-hard-requirement). Do not

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 197)May include surrounding context.

md
` | [references/prometheus-management.md](references/prometheus-management.md) |

External Script Fetching

High
Category
Supply Chain
Confidence
99% confidence
Finding

The skill references execution of a remote installer via curl -fsSL ... | bash, which is an unsafe pattern because it executes unreviewed network-fetched code directly in the shell. Given this is an agent skill intended to guide or automate operational tasks, the context makes the risk more dangerous: users may trust and execute the command without validation, leading to compromise of hosts, containers, or CI runners.

Content

Scanner excerpt · references/ai.md (reported line 207)May include surrounding context.

md
### OpenClaw / CoPaw / Hermes

- 各有专用 installer 脚本(`curl -fsSL ... | bash`),脚本自动安装对应可观测插件
- 参数通过 `--x-arms-license-key`、`--serviceName`、`--endpoint` 传入
- 仅 `opentelemetry` 协议,按 addon 模板输出即可

Credential Access

High
Category
Privilege Escalation
Confidence
70% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · references/ai.md (reported line 8)May include surrounding context.

md
## Scope

Guided workflow to onboard server-side applications into CMS Application Monitoring. Uses `aliyun cms2` CLI to initialize APM infrastructure and retrieve access credentials, then generates configuration for the user's specific language and deployment method.

**In-Scope**: Initialize APM infra, retrieve LicenseKey/Endpoint, register app services, generate startup configuration for all supported languages, **auto-modify K8s Deployment YAML** (with user confirmation) via `aliyun cs` + `kubectl`.

Credential Access

High
Category
Privilege Escalation
Confidence
70% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · references/apm.md (reported line 8)May include surrounding context.

md
## Scope

Guided workflow to onboard server-side applications into CMS Application Monitoring. Uses `aliyun cms2` CLI to initialize APM infrastructure and retrieve access credentials, then generates configuration for the user's specific language and deployment method.

**In-Scope**: Initialize APM infra, retrieve LicenseKey/Endpoint, register app services, generate startup configuration for all supported languages, **auto-modify K8s Deployment YAML** (with user confirmation) via `aliyun cs` + `kubectl`.

Credential Access

High
Category
Privilege Escalation
Confidence
68% confidence
Finding

Deriving region from kubeconfig context implies inspecting configuration that may embed sensitive cluster connection details. While this is less severe than explicitly fetching kubeconfig, it still normalizes credential-adjacent access within the workflow and can expose metadata not required if the user can simply provide or confirm the region.

Content

Scanner excerpt · references/apm.md (reported line 20)May include surrounding context.

md
> **CRITICAL** — When the user selects container (ACK/ACS/K8s) onboarding, the following rules are **absolute and non-negotiable**. Violating any of them is a workflow error.

1. **Do NOT ask user for `regionId`**: In container onboarding, `regionId` must be derived automatically from cluster metadata, workspace name, or kubeconfig context. Never prompt the user for region. If derivation fails, use `aliyun cs describe-clusters` output to extract `region_id` from cluster info.
2. **Do NOT run any `integration addon list` or `integration addon get` commands**: Container onboarding uses ack-onepilot component check + workload label patching. Addon discovery is exclusively for non-container (ECS/host) OpenTelemetry scenarios.
3. **Do NOT mention "Addon" to the user**: When asking the user to select onboarding type, use the prompt "请选择接入类型?" (not "请选择接入协议类型?(Addon 类型)" or any variant containing "Addon").
4. **Do NOT ask user for `network` type**: Container onboarding uses ack-onepilot label injection — there is no agent download URL or endpoint configuration, so public/VPC distinction is irrelevant. Skip the network question entirely.

Credential Access

High
Category
Privilege Escalation
Confidence
72% confidence
Finding

The workflow explicitly retrieves an authToken (LicenseKey) and endpoints, which are sensitive service credentials for telemetry submission. While necessary for onboarding, presenting or handling them without strong redaction and secret-handling guidance can lead to credential leakage, unauthorized telemetry injection, or misuse of the observability workspace.

Content

Scanner excerpt · references/apm.md (reported line 134)May include surrounding context.

Idempotent — if already initialized, returns successfully. Use apm configuration get to check status.

Step 3 — Retrieve Access Credentials

bash
aliyun cms2 apm configuration get --workspace {workspace} --region {regionId} -o json

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · references/apm.md (reported line 879)May include surrounding context.

md
### Prerequisites

- `kubectl` CLI is available locally
- AK/SK has ACK cluster read permissions (`cs:DescribeClusters`, `cs:DescribeClusterUserKubeconfig`)
- For ack-onepilot method: verify component is installed first. See [ack-onepilot Prerequisites](#prerequisites-install-ack-onepilot-component) for check and installation steps
- In container onboarding, do not ask user for `regionId`; derive it automatically from cluster/workspace/context when needed

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · references/apm.md (reported line 885)May include surrounding context.

Workflow

  1. Discover clusters and obtain kubeconfig:

    bash
    # List ACK clusters to find clusterId (only needed when clusterId is unknown)
    

Credential Access

High
Category
Privilege Escalation
Confidence
92% confidence
Finding

The command to retrieve cluster user kubeconfig for 480 minutes and save it to the default local config path creates a privileged session credential with substantial persistence. This increases the attack surface through accidental overwrite of existing contexts, credential leakage via logs/filesystem, and unintended reuse in subsequent kubectl operations.

Content

Scanner excerpt · references/apm.md (reported line 891)May include surrounding context.

List ACK clusters to find clusterId (only needed when clusterId is unknown)

aliyun cs describe-clusters --region {regionId}

Get kubeconfig for the target cluster (saved to ~/.kube/config by default)

aliyun cs describe-cluster-user-kubeconfig --cluster-id {clusterId} --temporary-duration-minutes 480

text

Credential Access

High
Category
Privilege Escalation
Confidence
92% confidence
Finding

The command to retrieve cluster user kubeconfig for 480 minutes and save it to the default local config path creates a privileged session credential with substantial persistence. This increases the attack surface through accidental overwrite of existing contexts, credential leakage via logs/filesystem, and unintended reuse in subsequent kubectl operations.

Content

Scanner excerpt · references/apm.md (reported line 891)May include surrounding context.

List ACK clusters to find clusterId (only needed when clusterId is unknown)

aliyun cs describe-clusters --region {regionId}

Get kubeconfig for the target cluster (saved to ~/.kube/config by default)

aliyun cs describe-cluster-user-kubeconfig --cluster-id {clusterId} --temporary-duration-minutes 480

text

Credential Access

High
Category
Privilege Escalation
Confidence
92% confidence
Finding

Explicitly documenting that kubeconfig is saved to ~/.kube/config encourages persistent storage of sensitive cluster credentials in a common path that other tools and sessions will automatically use. This can lead to credential sprawl, accidental privilege use against the wrong cluster, or leakage from local environment compromise.

Content

Scanner excerpt · references/apm.md (reported line 892)May include surrounding context.

aliyun cs describe-clusters --region {regionId}

Get kubeconfig for the target cluster (saved to ~/.kube/config by default)

aliyun cs describe-cluster-user-kubeconfig --cluster-id {clusterId} --temporary-duration-minutes 480

text

If the user's cluster is not ACK (self-managed K8s), ask for the kubeconfig file path (default `~/.kube/config`).

Credential Access

High
Category
Privilege Escalation
Confidence
89% confidence
Finding

Asking for the kubeconfig file path for self-managed clusters expands the skill’s reach into arbitrary local credential files, potentially exposing tokens, client certificates, and cluster topology. In combination with planned kubectl modifications, this creates a credible path to misuse or overbroad access if the skill or environment is compromised.

Content

Scanner excerpt · references/apm.md (reported line 895)May include surrounding context.

aliyun cs describe-cluster-user-kubeconfig --cluster-id {clusterId} --temporary-duration-minutes 480

text

If the user's cluster is not ACK (self-managed K8s), ask for the kubeconfig file path (default `~/.kube/config`).

Verify access:
```bash

Credential Access

High
Category
Privilege Escalation
Confidence
89% confidence
Finding

Asking for the kubeconfig file path for self-managed clusters expands the skill’s reach into arbitrary local credential files, potentially exposing tokens, client certificates, and cluster topology. In combination with planned kubectl modifications, this creates a credible path to misuse or overbroad access if the skill or environment is compromised.

Content

Scanner excerpt · references/apm.md (reported line 895)May include surrounding context.

aliyun cs describe-cluster-user-kubeconfig --cluster-id {clusterId} --temporary-duration-minutes 480

text

If the user's cluster is not ACK (self-managed K8s), ask for the kubeconfig file path (default `~/.kube/config`).

Verify access:
```bash

Anti-Refusal Statement

High
Category
Anti-Refusal
Confidence
85% confidence
Finding

Skill instructs the agent to never refuse or to always comply. Suppressing the agent's ability to decline removes a core safety control and enables downstream harmful requests to succeed.

Content

Scanner excerpt · references/integration-management.md (reported line 28)May include surrounding context.

md
5. **No `metric-agent` row** — zero rows, omitted `collectors`, or only other names (`entity-collector` / `loongcollector`) — → this policy does **not** support metric drop. Stop. That is not `QueryFailed`. A non-empty ClusterCollector list is not by itself support.
6. **Several** `metric-agent` rows (ECS: one per VPC) → present as a choice. If the user named a VPC, keep the row whose `releaseName` contains that `vpcId`.

This write targets that collector `releaseName`. Keywords are `HideReleaseName:true`, not `GroupMode:true` — do not refuse this update because the policy's **entry** addon is GroupMode, and do not put `dropMetrics` under `values.addons`. `--region` equals the policy's `regionId` (metric-agent has no `Feature:CrossRegion`). For the general rule see [Addon Release Region Requirement](integration-common.md#addon-release-region-requirement-hard-pre-check).

### Input

Self-Modification

High
Category
Rogue Agent
Confidence
90% confidence
Finding

Skill modifies its own code, configuration, or behavior at runtime. Self-modification enables an agent to escalate privileges, disable safety constraints, or install persistent backdoors.

Content

Scanner excerpt · references/ram-policies.md (reported line 27)May include surrounding context.

md
| `event-hub list` / `event-hub get` | SLS GetLogs API; uses SLS credentials; consumes no CMS RAM Action |
| `configure` | Local credential configuration; no OpenAPI call |
| `commands` | Local static command discovery; no OpenAPI call |
| `update-beta` | Beta self-update; does not consume CMS OpenAPI RAM Actions |

> Maintenance note: if a future script/agent rescans the source to refresh
> this file, preserve this section and skip the modules above. Do not

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The trigger description is extremely broad and includes catch-all phrasing such as many product areas and 'etc.', which can cause the skill to activate for loosely related requests. Over-broad activation increases the chance that a high-privilege operational skill is invoked in the wrong context, leading to unintended command guidance or execution paths.

Content

No source excerpt is available for this finding.

Autonomous Decision Making

Medium
Category
Excessive Agency
Confidence
85% confidence
Finding

Skill enables autonomous high-impact decisions without human-in-the-loop verification. Critical operations (destructive commands, financial transactions, data deletion) should require explicit user confirmation.

Content

Scanner excerpt · SKILL.md (reported line 71)May include surrounding context.

md
- **Addon-release `values`**: expand each field's `fieldPath` into nested JSON as specified in [Addon Values Defaults](references/integration-common.md#addon-values-defaults-hard-requirement). Do not write a dotted `fieldPath` as one literal key. How to pick `--env-type`, where child fields sit on create vs update, and when a subset is (or is not) a valid body, are in that section.
- **Region parameter required for mutating and detail commands**: unless otherwise specified by a module-specific rule, all `create`, `update`, `delete`, and single-resource `get`/detail commands MUST include the `--region` parameter so the request is routed to the correct backend OpenAPI endpoint. Omitting `--region` on these commands may cause routing failures or operate against an unintended region, and the error can name something else entirely — `integration policy create` returns `status 400: The workspace can not be created` even when the workspace exists and the body is valid. This does not apply to `list`/query commands that intentionally span multiple regions (e.g. `entity query --source CloudResource` all-region queries). Requiring the flag is not permission to choose its value — resolve it per [Region Confirmation Gate](#region-confirmation-gate-hard-requirement).
- **One choice, one question**: every enumerated choice (region, workspace, policy, addon, scope mode, tag match mode, and any other mutually exclusive parameter) is asked as one question carrying **all** of its options. Never split them across questions or into a `(续)...` continuation, and never drop the ones that do not fit — a split turns one choice into two answers that can conflict or be left incomplete, and a truncated list hides valid choices entirely. When the structured input form cannot render every option, ask as plain text and spell out every option with its explanation in the question body. A mutually exclusive choice stays single-select; only a genuinely multi-valued one (several regions) is multi-selec
...[truncated 26 chars]

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The instruction says to default to Simplified Chinese when the user's language is unclear or mixed, which forces a specific output language without explicit user choice. The policy allows language constraints only when the user opts in or when the limitation is clearly justified as region-specific.

Content

No source excerpt is available for this finding.

Context Window Stuffing

Medium
Category
Memory Poisoning
Confidence
80% confidence
Finding

Skill attempts to fill the context window with filler content, displacing legitimate instructions and safety constraints. This can degrade agent performance or bypass safety boundaries.

Content

Scanner excerpt · SKILL.md (reported line 187)May include surrounding context.

md
## Module Routing

| User Intent Keywords                                                                                                                                                                                                                                                                                                   | Commands | Module |
|------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------|----------|--------|
| onboarding, monitoring addon, policy, integration, addon release, integration resource, Kubernetes resource list, Namespace resources under policy, resources managed by policy, teardown, offboarding — **common rules, load for every onboarding operation**                                                          | `integration` `integration resource` | [references/integration-common.md](references/integration-common.md) |
| container onboarding, ACK/ACS/ASI cluster onboarding, cluster fleet audit, which clusters are not onboarded                                                                                                                                                                                                            | `integration` `entity query` | [references/cs-onboarding.md](references/cs-onboarding.md) (+ integration-common.md) |

Context Window Stuffing

Medium
Category
Memory Poisoning
Confidence
80% confidence
Finding

Skill attempts to fill the context window with filler content, displacing legitimate instructions and safety constraints. This can degrade agent performance or bypass safety boundaries.

Content

Scanner excerpt · SKILL.md (reported line 191)May include surrounding context.

md
## Module Routing

| User Intent Keywords                                                                                                                                                                                                                                                                                                   | Commands | Module |
|------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------|----------|--------|
| onboarding, monitoring addon, policy, integration, addon release, integration resource, Kubernetes resource list, Namespace resources under policy, resources managed by policy, teardown, offboarding — **common rules, load for every onboarding operation**                                                          | `integration` `integration resource` | [references/integration-common.md](references/integration-common.md) |
| container onboarding, ACK/ACS/ASI cluster onboarding, cluster fleet audit, which clusters are not onboarded                                                                                                                                                                                                            | `integration` `entity query` | [references/cs-onboarding.md](references/cs-onboarding.md) (+ integration-common.md) |

Static analysis

No suspicious patterns detected.